Data duplication method in a disaster recovery system
Summary by NHIP
Remote disaster recovery system
The system executes database recovery on a remote site using logs containing update differences and commands. It generates snapshots by instructing a storage unit to switch a mirror set from a pair state to a split state after synchronizing data across multiple volumes.
Claim Score by NHIP
Abstract
A recovery of a secondary DB is executed by a log including a update difference of a primary DB, and a command is executed by adding the command to the log and analyzing the log by a secondary site. An operation command execution in the secondary site is applied to the DB having the consistency in the transaction at the same timing as a primary site or an intended timing, by transferring and executing the operation command via the log. In the case that the command is constituted by a snap shot generating instruction, a plurality of volumes of a mirror set forming a secondary storage apparatus are set to a pair state and the secondary DB is written in each of the volumes and synchronized, and the mirror set is set to a split state after the synchronization is finished, whereby a secondary DB is stored.

Term
Term ended
Expired 11 August 2026, 0.1 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
14 claims: 3 independent, 11 dependent
- 1The disaster recovery system executing a backup operation while arranging a first system and a second system in remote locations, wherein the first system comprises:a first calculating machine executing a first DBMS providing the first database;a first storage for storing a log to which an update difference of the first database is output at each of transactions, and the first database;a command adding unit for adding a command to the log;and a remote copy unit transferring the log to the second system, wherein the second system comprises: a second storage for storing a log received from the first system and a second database;and a database recovering unit for recovering the second database on the basis of the log received from the first system, and wherein the database recovering unit comprises: a command extracting section for extracting the command included in the log;and a command executing section for executing the extracted command, wherein the command adding unit adds to the log a snapshot generating command for instructing a snapshot generation as an instruction output to the second system, wherein the second storage has a mirror set capable of changing a plurality of volumes between a pair state and a split state, wherein the command executing section instructs the second storage to generate the snapshot in the case that the extracted command is constituted by a snapshot generating command, and wherein the second storage stores the mirror set in the second database under a split state after writing the second database in a plurality of volumes so as to synchronize by setting the mirror set to a pair state, on the basis of the snapshot generating instruction.
- 6The disaster recovery system executing a backup operation while arranging a first system and a second system in remote locations, wherein the first system comprises:a first calculating machine executing a first DBMS providing the first database;a first storage for storing a log to which an update difference of the first database is output at each of transactions, and the first database;a command adding unit for adding a command to the log;and a remote copy unit transferring the log to the second system, wherein the second system comprises: a second storage for storing a log received from the first system and a second database;and a database recovering unit for recovering the second database on the basis of the log received from the first system, and wherein the database recovering unit comprises: a command extracting section for extracting the command included in the log;and a command executing section for executing the extracted command, wherein the command adding unit adds to the log a snapshot generating command instructing a snapshot generation as an instruction output to the second system, wherein the second storage has a mirror set capable of changing a plurality of volumes between a pair state and a split state, wherein the database recovering unit has a transaction control unit which reads the log from the second storage to determine a non-determined transaction of the second database, wherein the command executing section instructs the second storage to generate the snapshot in the case that the extracted command is constituted by a snapshot generating command, and wherein the second storage switches the mirror set from a pair state to a split state on the basis of the snapshot generating instruction to store the second database obtained by determining the transaction.
- 7Broadest claimClaim Score 39, average(NHIP)The remote command execution method of duplicating the data from a first database executed by a first system to a second database duplicated in a second storage provided in a second system, comprising:a process of recording a log of a update difference of the first database in a first storage;a process of writing the update difference of the first database in the first storage;a process of combining a command applied to the first or second system with the log;a process of transferring the log including the update difference and the command to the second system;a process of storing the transferred log in the second storage;a process of reading the log of the second storage and recovering the second database on the basis of the log of the update difference;a process of extracting the command from the log of the second storage;and a process of executing the extracted command, wherein the process of combining the command with the log includes a process of combining with the log a snapshot preparing command for instructing a preparation of a snapshot by the second system, and wherein the process of executing the extracted command includes: a process of setting a plurality of volumes of a mirror set constituting the second storage to a pair state so as to write the second database in each of the volumes to synchronize to each other in the case that the extracted command is a snapshot preparing command;and a process of setting the mirror set to a split state so as to store the second database after the synchronization is finished.
Independent claims3
184 paragraphs in 6 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATION
p-0002The present application claims priority from Japanese Patent Application No. JP 2004-223776 filed on Jul. 30, 2004, the content of which is hereby incorporated by reference into this application.
p-0003The present application is related to the following prior U.S. applications, the disclosures of which are hereby incorporated by reference into this application:
p-0004(1) U.S. Ser. No. 10/849006, filed May 20, 2004
p-0005(2) U.S. Ser. No. 10/184246, filed Jun. 26, 2004
p-0006(3) U.S. Ser. No. 10/819191, filed Apr. 7, 2004
p-0007(4) U.S. Ser. No. 10/650842, filed Aug. 29, 2003.
TECHNICAL FIELD OF THE INVENTION
p-0008The present invention relates to an improvement of a disaster recovery system, and more particularly to a disaster recovery system suitable for a database.
BACKGROUND OF THE INVENTION
p-0009In recent years, an information technology (IT) system is indispensable in business, and it is important to continue the business even in the case of a disability or a disaster. An opportunity loss caused by the IT system stop is enormous, for example, is said to amount to some millions dollar in a banking business and a large company. In view of the background mentioned above, a disaster recovery (hereinafter, refer to DR) system is paid attention, the DR system being structured such as to prepare two sites comprising primary and secondary sites capable of actuating the database, back up business data to the secondary site at a usual time and continue the operation by the secondary site at a disaster time.
p-0010In the DR system, each of the primary site and the secondary site is provided with a database (hereinafter, refer to DB) server and a storage apparatus from a usual time. Accordingly, great much cost is required for constructing and maintaining the DR system such as construction and control costs of the primary and secondary sites, a circuit cost and the like. However, it is said that a probability at which the disaster is actually generated is some % in all the disability. Accordingly, in recent years when it is desired to make the business efficient and reduce the cost, an added value is required in the DR system.
p-0011As one example of the added value mentioned above, there is a backup system corresponding to Rolling Disaster in which the DR system is highly developed.
p-0012The Rolling Disaster means that each of the system constituting elements is gradually broken at different timings at a time when the disaster is generated, in place that the system constituting elements are broken simultaneously. Accordingly, update of the data is transferred from the primary site to the secondary site on and after the disaster is generated, so that there is generated a possibility that a consistency is not secured in the data backed up in the secondary site.
p-0013In order to cope with the Rolling Disaster mentioned above, there is known a structure which stores a point in time (PiT) image before the disaster is generated, in addition to a most recent PiT image in the database (for example, Claus Mikkelsen, “The Hitachi NanoCopy Advantage”, pp. 9-11, [online], “searched on Jul. 16, 2004”, via the Internet http://www.hds.com/pdf/wp134_nanocopy.pdf).
p-0014This is structured such that the secondary site is provided with a first volume and a second volume, the primary site repeats interruption and recovery of a remote copy by a timer, the secondary site records the remote copy in the first volume at a time of receiving the remote copy, and when the remote copy is interrupted, the secondary site copies the data from the first volume to the second volume after confirming that the primary site has no disability, thereby preparing the PiT image at that time point. When the primary site returns the remote copy, the secondary site writes the date in the first volume. Accordingly, the secondary site always stores most recent generation of backup (the first volume) and one generation anterior backup (the second volume), and even if the writing is executed in the first volume due to the Rolling Disaster, it is possible to return on the basis of the one generation anterior backup stored in the second volume.
p-0015Another example which gives the added value of the DR system, there is known a structure which executes a searching process of the DB in addition to the backup, by the secondary site which has a lower load than the primary site (for example, “Oracle Data Guard”, “Overview of Oracle Data Guard Functional Components”, [online], “Searched on Jul. 16, 2004”, via the Internet, http://otn.oracle.com/deploy/availability/htdocs/DataGuardOverv iew.html).
p-0016This is structured such that each of the primary site and the secondary site is provided with a database management system (DBMS) and a storage apparatus, and the primary and secondary sites are connected only by a network between servers. Further, the DBMS of the primary site transfers log to the DBMS of the secondary site at the same time of writing the data in the storage apparatus. The DBMS of the secondary site writes the received log in the storage apparatus. Further, in the secondary site, the DB is updated by applying the log written in the storage apparatus to the DB of the secondary site at the time of not executing the operation such as the searching process or the like.
SUMMARY OF THE INVENTION
p-0017In the former conventional art (non-patent document 1), since the one generation anterior backup is acquired at a predetermined time interval, there is a problem that it is hard to back up the data just before the disaster is generated. Further, the secondary site copies the volume base by the first and second volumes, the consistency of the stored backup is not assured in a transaction level. Accordingly, in order to activate the DB by the backup of the secondary site, it is necessary to carry out a process for recovering the consistency of the transaction, so that there is a problem that a lot of time is required for recovering the DB.
p-0018Further, in the latter conventional art, the DB is recovered by activating the DBMS by the secondary site from the usual time and applying the log from the primary site to the DB of the secondary site, and the added value of the DR system is attempted to improve by executing the searching process. However, in the case of executing the log application, it is necessary to interrupt the searching process, so that there is a problem that it is impossible to always provide the business. This is because the consistency in the transaction level is not assured as mentioned above, even if the DB is recovered by the log application. In order to secure the consistency in the transaction level, it is necessary to carry out a process of analyzing the log in the transaction level, and the process can not be executed in parallel to the log application mentioned above.
p-0019Accordingly, the present invention is made by taking the problem mentioned above into consideration, and an object of the present invention is to recover a database with no deficit of data by preparing a backup having a consistency in a transaction level, and another object of the present invention is to improve an added value of a DR system by making an operation of a secondary site easy and providing a business by the secondary site.
p-0020In accordance with the present invention, there is provided a data duplication method of duplicating a first database executed by a first system to a second database stored in a second storage provided in a second system, comprising: a process of recording a log of a update difference of the first database in a first storage; a process of writing the update difference of the first database in the first storage; a process of adding an operation command applied to the first or second system to the log; a process of transferring the log including the update difference and the command to the second system; a process of storing the transferred log in the second storage; a process of reading the log of the second storage and recovering the second database on the basis of the log of the update difference; a process of extracting the command from the log of the second storage; and a process of executing the extracted command, thereby controlling the second system via the log.
p-0021Further, the process of adding the command to the log includes a process of adding to the log a snap shot preparing command for instructing a preparation of a snap shot by the second system, and the process of executing the extracted command includes a process of setting a plurality of volumes of a mirror set constituting the second storage to a pair state so as to write the second database in each of the volumes and synchronize, and a process of setting the mirror set to a split state so as to store the second database after the synchronization is finished, in the case that the extracted command is a snap shot preparing command.
p-0022Further, when preparing the snap shot, the first and second databases are staticized.
p-0023In this case, the operation command may be constituted by DBMS or OS, or an application command, in addition to the snap shot.
p-0024Accordingly, the present invention can control from the first system to the second system by executing the recovery of the second data by the log including the update difference of the first database and adding the command to the log while achieving the recovery of the database with no deficit.
p-0025Further, since the operation command is transferred and executed by the log application, it is possible to execute the operation command at the same timing with respect to the database in the same state in which the transaction consistency is secured in the primary and secondary sites (the first system and the second system) with respect to the database.
p-0026In the case of using for the snap shot preparation, if the snap shot preparation is instructed, the second database can be stored by setting a plurality of volumes of the mirror set constituting the second storage to the pair state so as to write the second database to each of the volumes and synchronize, and setting the mirror set to the split state after finishing the synchronization. Since the second database stored in this manner can be utilized in the second system independently from the first system, it is possible to improve the added value of the disaster recovery system in which a lot of cost is required for construction and operation.
p-0027In particular, since the first and second database are staticized, it is possible to easily prepare the backup (the snap shot) having the consistency in the transaction level.
BRIEF DESCRIPTIONS OF THE DRAWINGS
p-0028<figref idrefs="DRAWINGS">FIG. 1</figref> shows an embodiment in accordance with the present invention, and is a block diagram of a system in the case a disaster recovery is executed by two sites;
p-0029<figref idrefs="DRAWINGS">FIG. 2</figref> is a block diagram showing a software structure of a primary DBMS of a primary site;
p-0030<figref idrefs="DRAWINGS">FIG. 3</figref> is a block diagram showing a software structure of a DB/storage control unit of a secondary site;
p-0031<figref idrefs="DRAWINGS">FIG. 4</figref> is a flow chart showing an example of a process executed in the primary DBMS of the primary site;
p-0032<figref idrefs="DRAWINGS">FIG. 5</figref> is a flow chart showing an example of a process executed in the DB/storage control unit of the secondary site;
p-0033<figref idrefs="DRAWINGS">FIG. 6</figref> shows a second embodiment, and is a block diagram showing a structure of an exclusive apparatus of the secondary site;
p-0034<figref idrefs="DRAWINGS">FIG. 7</figref> shows the second embodiment, and is a flow chart showing an example of a process executed in the DB/storage control unit of the secondary site;
p-0035<figref idrefs="DRAWINGS">FIG. 8</figref> shows a first modified embodiment, and is a flow chart showing an example of a process executed in the DB/storage control unit and a secondary DBMS of the secondary site;
p-0036<figref idrefs="DRAWINGS">FIG. 9</figref> shows a second modified embodiment, and is a block diagram of a system in the case that the disaster recovery is executed by two sites;
p-0037<figref idrefs="DRAWINGS">FIG. 10</figref> shows a third modified embodiment, and is a block diagram of a system in the case that the disaster recovery is executed by two sites; and
p-0038<figref idrefs="DRAWINGS">FIG. 11</figref> shows the third modified embodiment, and is a block diagram of a system in the case that an operation command is executed by two sites, in which <figref idrefs="DRAWINGS">FIG. 11A</figref> shows an original state, <figref idrefs="DRAWINGS">FIG. 11B</figref> shows a state in which the operation command is executed in the primary site, and <figref idrefs="DRAWINGS">FIG. 11C</figref> shows a state in which the operation command is executed in the secondary site.
DESCRIPTION OF THE PREFERRED EMBODIMENTS
p-0039A description will be given below of an embodiment in accordance with the present invention with reference to the accompanying drawings.
p-0040<figref idrefs="DRAWINGS">FIG. 1</figref> shows a typical system view used in the present invention, and shows an embodiment in which a disaster recovery is executed by two sites (systems).
p-0041In <figref idrefs="DRAWINGS">FIG. 1</figref>, a primary site (a first system) <b>1</b> is mainly constituted by a primary server <b>100</b> wherein a primary database management system (DBMS) <b>101</b> is operated and by a primary storage apparatus <b>103</b> storing a primary database <b>107</b> controlled by the primary DBMS <b>101</b>.
p-0042A secondary site (a second system) <b>2</b> is mainly constituted by a secondary sever <b>110</b> wherein a secondary DBMS <b>111</b> is operated, a secondary storage apparatus <b>113</b> storing secondary databases <b>117</b> and <b>118</b> controlled by the secondary DBMS <b>111</b>, and an exclusive apparatus (an intermediate apparatus) <b>400</b> executing a DB/storage control unit <b>300</b> corresponding to a sub set obtained by offloading (dividing) a part (a log application=database recovery function) of a DBMS function of the secondary DBMS <b>111</b>. In this case, the exclusive apparatus <b>400</b> is arranged between the secondary sever <b>110</b> and the secondary storage apparatus <b>113</b>, and is provided with CPU and a memory which are not illustrated.
p-0043Further, in the primary site <b>1</b> and the secondary site <b>2</b>, the server and the storage apparatus are independently connected via a network <b>121</b> between servers connecting the primary server <b>100</b> and the secondary sever <b>110</b>, and a network <b>120</b> between storage connecting the primary storage apparatus <b>103</b> and the secondary storage apparatus <b>113</b>. Further, the primary storage apparatus <b>103</b> transfers an update data (a log of the primary DB <b>107</b>) to the secondary storage apparatus <b>113</b>, and in the secondary site <b>2</b>, the secondary storage apparatus <b>113</b> stores a backup of the primary database (DB) <b>107</b> in the primary site <b>1</b>.
p-0044To the server network <b>121</b>, there are connected a control apparatus <b>200</b> controlling the primary and secondary sites <b>1</b> and <b>2</b>, and a client computer <b>250</b> accessing to the primary DBMS <b>101</b> or the secondary DBMS <b>101</b>.
p-0045The control apparatus <b>200</b> is constituted, for example, by a calculating machine such as a server in which a monitoring program (Monitor in the drawing) <b>501</b> is executed, detects a heartbeat of the primary server <b>100</b>, detects a disability of the primary site <b>1</b> on the basis of a disability information of the primary storage apparatus <b>103</b> and the like, instructs a fail over to a DB/storage control unit <b>300</b> and the secondary sever <b>110</b> of the secondary site <b>2</b> at a time of detecting the disability, and have the secondary site <b>2</b> taking over the operation.
p-0046The client computer <b>250</b> is constituted, for example, by a calculating machine in which a business program (UAP=user application in the drawing) <b>500</b> is executed. The business program <b>500</b> of the client computer <b>250</b> accesses to the primary DBMS <b>101</b> with respect to a process of referring and renewing the primary DB <b>107</b> at a normal time. Further, it can access to the secondary DBMS <b>111</b> with respect to the primary DB <b>107</b> searching and referring operation.
p-0047In the case that the disability is generated in the primary site <b>1</b>, the business program <b>500</b> of the client computer <b>250</b> accesses to the secondary DBMS <b>111</b> with respect to all the processes such as the updating process of the primary DB <b>107</b> and the searching and referring operation.
p-0048The primary site <b>1</b> is constituted by the primary server <b>100</b> and the primary storage apparatus <b>103</b>. The primary server <b>100</b> is provided with CPU and a memory which are not illustrated, and the primary DBMS <b>101</b> of the primary DB <b>107</b> is installed in the primary server <b>100</b>. The primary DBMS <b>101</b> accepts the operation from the client computer <b>250</b> and the control apparatus <b>200</b>.
p-0049The primary DBMS <b>101</b> controls the primary database (DB) <b>107</b> by using a DB buffer <b>102</b> on the memory of the primary server <b>100</b> and the primary storage apparatus <b>103</b>.
p-0050The primary DB <b>107</b> is stored in the disc storage unit <b>130</b> of the primary storage apparatus <b>103</b>, however, normally executes a updating process on the DB buffer <b>102</b> because accessing to the primary storage apparatus <b>103</b> every time when the update is executed lowers a processing speed of the primary DBMS <b>101</b>.
p-0051The primary DBMS <b>101</b> reflects the update of the primary DB <b>107</b> on the primary storage apparatus <b>103</b> at a preset timing in the case that the transaction (Tr) of the primary DB <b>107</b> is committed, or the case that the DB buffer <b>102</b> overflows or the like.
p-0052The primary storage apparatus <b>103</b> is constituted by a cash <b>105</b>, a disc control program <b>104</b>, a control apparatus (not shown), a plurality of disc storage units <b>130</b> and <b>131</b>, and a plurality of volumes set in the disc storage units. A data main body of the primary DB <b>107</b> is stored in each of the volumes, and a log <b>106</b> having information of update difference to the data (the primary DB <b>107</b>) is stored therein. In this case, the control apparatus of the primary storage apparatus <b>103</b> is provided with CPU and a memory which are not illustrated.
p-0053The disc control program <b>104</b> executed by the control apparatus of the primary disc storage unit <b>103</b> controls a remote copy with respect to the secondary storage apparatus <b>113</b> of the secondary site <b>2</b> via the storage network <b>120</b>. In this case, only the log <b>106</b> is transferred in accordance with a synchronous remote copy or an asynchronous remote copy.
p-0054In other words, the primary DBMS <b>101</b> generates the log <b>106</b> indicating the update difference of the written data so as to write in the primary storage apparatus <b>103</b> before writing (renewing) the contents of the DB buffer <b>102</b> in the primary DB <b>107</b> of the primary storage apparatus <b>103</b>. The disc control program <b>104</b> transfers the newly added log <b>106</b> to the secondary storage apparatus <b>113</b> via the storage network <b>120</b> at the predetermined timing as mentioned above.
p-0055The secondary site <b>2</b> is constituted by the secondary sever <b>110</b>, the secondary storage apparatus <b>113</b> and an exclusive apparatus <b>400</b> executing a DB/storage control unit <b>300</b> including a partial function (for example, a log applying function) of the secondary DBMS <b>111</b>.
p-0056In this case, the exclusive apparatus <b>400</b> may be constituted by a calculating machine provided with a processing capacity capable of executing the DB/storage control unit <b>300</b>, does not require a processing capacity capable of executing the secondary DBMS <b>111</b>, and can be constituted by a calculating machine having a lower processing capacity than the secondary sever <b>110</b>.
p-0057The secondary DBMS <b>111</b> of the secondary sever <b>110</b> provides the searching and referring operation to the client computer <b>250</b> by using the secondary DB <b>118</b> backed up (being snapshot) to the secondary storage apparatus <b>113</b> at the normal time as mentioned below. Further, in the case that the disability is generated in the primary site <b>1</b>, the secondary DBMS <b>111</b> takes over the primary DBMS <b>101</b> and executes the business.
p-0058The secondary storage apparatus <b>113</b> is provided with a disc control program <b>114</b> having a remote copy function, a cash <b>115</b>, and a local mirror set <b>350</b> structured by a plurality of disc storage units.
p-0059The secondary storage apparatus <b>113</b> is provided with a plurality of disc storage units <b>301</b>, <b>302</b> and <b>303</b>, and a log <b>116</b> stored by the remote copy and controlled by the primary DBMS <b>101</b> is stored in a volume formed in the disc storage unit <b>303</b>.
p-0060The disc storage units <b>302</b> and <b>303</b> structure the local mirror set <b>350</b>, and a backup <b>117</b> (i generation in the drawing) of the most recent primary DB <b>107</b>, and a backup <b>118</b> (i-<b>1</b> generation in the drawing) of the proximate primary DB <b>107</b> are respectively stored in a plurality of volumes set in the disc storage units <b>302</b> and <b>303</b>. In this case, it is assumed that the disc storage units <b>302</b> and <b>303</b> have respective one volumes <b>310</b> and <b>320</b>. In this case, in the present embodiment, the volume <b>310</b> is a primary volume, and the volume <b>320</b> is a secondary volume.
p-0061The local mirror set <b>350</b> can execute a writing and reading control as the single volume <b>310</b> or <b>320</b>, respectively, in a state in which the disc control program <b>114</b> splits (divides) a pair relation of a mirroring on the basis of the instruction from the DB/storage control unit <b>300</b>, and stops the synchronization between the volumes. Further, in the case that a pair state is set by finishing the split, the mirroring is executed from the primary volume <b>310</b> to the secondary volume <b>320</b>.
p-0062The backup of the primary DB <b>107</b> in the primary site <b>1</b> normally sets the volumes <b>310</b> and <b>320</b> to the split state and stores the most recent backup <b>117</b> only in the volume <b>310</b>.
p-0063Further, on the basis of a predetermined timing (a requirement from a controller or a monitoring program <b>501</b> of the control apparatus <b>200</b>, or the like), the DB/storage control unit <b>300</b> returns the local mirror set <b>350</b> to the pair state, and copies the contents of the volume <b>310</b> to the volume <b>320</b>, thereby synchronizing two volumes <b>310</b> and <b>320</b>. In accordance with the synchronization, the backup <b>118</b> of the volume <b>320</b> is updated to the most recent contents (generation). At this time, the DB/storage control unit <b>300</b> reads the backed up log <b>116</b>, and determines all transaction of the backed up secondary DB <b>117</b>. The contents (the secondary DB <b>118</b>) of the copied volume <b>320</b> forms the snap shot of the primary DB <b>107</b> having the consistency in the transaction by executing the mirroring thereafter, whereby it is possible to assure the contents of the searching and referring operation executed by the secondary DBMS <b>111</b>. In this case, in the present embodiment, there is shown a case that the monitoring program <b>501</b> of the control apparatus <b>200</b> requires the preparation of the snap shot to the primary site <b>1</b> at a predetermined cycle.
p-0064Thereafter, the DB/storage control unit <b>300</b> again sets the volumes <b>310</b> and <b>320</b> to the split state of the mirroring, and stores the most recent backup <b>117</b> only to the volume <b>310</b>. Accordingly, the contents of the volume <b>320</b> is not updated by the remote copy until the next mirroring time, and it is possible to maintain the secondary DB <b>118</b> corresponding to the most recent snap shot having the consistency in the transaction level.
p-0065In the remote copy from the primary storage apparatus <b>103</b>, only the log <b>116</b> including the information of the update difference of the primary DB <b>107</b> and the command from the primary DBMS <b>101</b> is transferred from the primary storage apparatus <b>103</b> to the secondary storage apparatus <b>113</b> in accordance with a remote copy function.
p-0066As discussed above, the remote copy may be constituted by the synchronous remote copy or the asynchronous remote copy. In the case of the synchronous remote copy, since the writing of the data of the primary DB <b>107</b> in the primary storage apparatus <b>103</b> is finished only after the writing in the secondary storage apparatus <b>113</b> is finished, it is possible to assure the copy of the data with no deficit even if the disaster or the disability is generated.
p-0067However, since a circuit delay of the server network <b>121</b> is added every writing time, an influence to the operation executed in the primary DBMS <b>101</b> is not negligible. On the other hand, in the case of using the asynchronous remote copy, since the process is continued on the assumption that the writing of the data in the primary storage apparatus <b>103</b> has been finished before the transferring to the secondary storage apparatus <b>113</b> is executed, the influence to the primary DBMS <b>101</b> is restricted to the minimum. However, in the case that the disaster is generated before the writing in the secondary storage apparatus <b>113</b> is finished, the deficit is generated.
p-0068After the starting time of the recovery, the secondary DB <b>117</b> is recovered by the log application in spite of the remote copy. The log application is executed by the exclusive apparatus <b>400</b> arranged between the secondary storage apparatus <b>113</b> and the secondary sever <b>110</b>.
p-0069A log applying function corresponding to one function of the secondary DBMS <b>111</b> is offloaded to the exclusive apparatus <b>400</b> so as to form the DB/storage control unit <b>300</b> serving as the sub set of the secondary DBMS <b>111</b>. Since it is sufficient that the exclusive apparatus <b>400</b> executes only the log application, the exclusive apparatus <b>400</b> has a low processing capacity and can be achieved by an inexpensive calculating machine. Accordingly, since it is sufficient that only the exclusive apparatus <b>400</b> is provided at the normal time, and it is not necessary to place the secondary sever <b>110</b> in the case that the searching and referring operation is not executed, it is possible to construct the DR system at a more inexpensive cost.
p-0070Further, since the DB/STORAGE control apparatus <b>300</b> serving as the subset has the limited function, it is not necessary to execute a complex management in comparison with the case of the secondary DBMS <b>111</b> having a full function, and it is possible to achieve a low cost performance in view of the operation management.
p-0071Further, in <figref idrefs="DRAWINGS">FIG. 1</figref>, the exclusive apparatus <b>400</b> is provided only in the secondary site <b>2</b> but the exclusive apparatus may be provided also in the primary site <b>1</b>. For example, there is a case that a system (site) switching process is executed in accordance with a plan in addition to the time of the disaster. In this case, it is necessary to counterchange roles of the primary site <b>1</b> and the secondary site <b>2</b>, whereby the business is executed by the secondary site, and the recovering process is executed by the primary site. In this case, it is necessary to counterchange a source from which the remote copy of the logs <b>106</b> and <b>107</b> is copied, and a destination to which the remote copy of the logs <b>106</b> and <b>107</b> is copied, and it is necessary to recover the primary DB <b>107</b> by the exclusive apparatus in the primary site.
h-0007[Software Structure of Primary DBMS <b>101</b>]
p-0072A software structure of the primary DBMS <b>101</b> in the primary site <b>1</b> is shown in <figref idrefs="DRAWINGS">FIG. 2</figref>.
p-0073The primary DBMS <b>101</b> is constituted by a transaction accepting unit <b>502</b> accepting a requirement from the business program <b>500</b> of the client computer <b>250</b>, a transaction control unit <b>503</b> confirming a consistency of the transaction to be processed and executing the transaction, a DB control unit <b>505</b> executing the updating and the referring to the DB buffer <b>102</b> or the primary storage apparatus <b>103</b>, a control unit <b>504</b> generating a update difference executed by the DB control unit <b>505</b> as a log, and generating an operation command for controlling the DB <b>107</b> and the secondary DB <b>117</b> and <b>118</b> of the secondary site <b>2</b> as a log, and an operation command execution control unit <b>506</b> accepting the requirement from the monitoring program <b>501</b> of the control apparatus <b>200</b> or the like as a command, and controlling the primary storage apparatus <b>103</b> or the secondary storage apparatus <b>113</b> of the sub site <b>2</b>.
p-0074The operation command execution control unit <b>506</b> is constituted by an operation command accepting unit <b>507</b> accepting the requirement such as the snap shot forming or the like from the control apparatus <b>200</b> or the like, an operation command control unit <b>508</b> controlling an execution of the accepted operation command, and an operation command issuing unit <b>509</b> sending the control instruction in the primary storage apparatus <b>103</b> to the disc control program <b>104</b> on the basis of the operation command. In this case, the operation command may be constituted by the command of the DBMS, the OS and the application, and in this case, the command is issued to the DBMS, the OS and the application.
p-0075In order to control an executing timing of the accepted operation command, the operation command control unit <b>508</b> inquires the transaction control unit <b>503</b> about a determining state of the transaction, and sends an instruction required for executing the operation command to the operation command issuing unit <b>509</b>. Further, in the case that it is necessary to execute the accepted operation command in the secondary site <b>2</b> in addition to the primary site <b>1</b>, the operation command control unit <b>508</b> sends an instruction to the transaction control unit <b>503</b> so that the operation command is included in the log <b>106</b>, and the transaction control unit <b>503</b> sends the operation command to the log control unit <b>504</b>, and writes the operation command in the log <b>106</b>.
p-0076For example, the accepted operation command is constituted by the snap shot forming, the operation command control unit <b>508</b> inquires the transaction control unit <b>503</b> about whether or not all the transactions have been determined.
p-0077If there is any transaction which is not determined, the operation command control unit <b>508</b> executes a staticization for forcibly determining all the transactions.
p-0078When the staticization is finished, the operation command control unit <b>508</b> sends an instruction to the transaction control unit <b>503</b> so as to write the snap shot preparing command in the log <b>106</b> after the staticizing command.
p-0079The transaction control unit <b>503</b> sends an instruction to the log control unit <b>504</b>, prepares the log <b>106</b> in the order of the staticizing command and the snap shot preparation, and makes the disc control program <b>104</b> a request for writing.
p-0080The disc control program <b>104</b> executes the remote copy at a predetermined timing (a predetermined cycle or a update time of the log <b>106</b>), the information of the update difference of the primary DB <b>107</b> and the log <b>106</b> including the operation command are transferred to the secondary storage apparatus <b>113</b> of the secondary site <b>2</b>, and the secondary site <b>2</b> executes the backup of the primary DB <b>107</b> and the operation command from the primary DBMS <b>101</b>, by analyzing the backed up log <b>116</b>.
h-0008[Software Structure of DB/Storage Control Unit in Secondary Site <b>2</b>]
p-0081<figref idrefs="DRAWINGS">FIG. 3</figref> shows a structure of a software mainly constituted by the DB/storage control unit <b>300</b> of the secondary site <b>2</b>.
p-0082The DB/storage control unit <b>300</b> is provided with a log monitoring unit <b>360</b> reading and monitoring the log <b>116</b> backed up from the primary site <b>1</b>, a transaction control unit <b>361</b> instructing a DB control unit <b>362</b> such that if the log <b>116</b> read from the log monitoring unit <b>360</b> is a log indicating the update difference of the primary DB <b>107</b>, the log is applied to the secondary DB <b>117</b> of the volume <b>310</b>, and if the read log <b>116</b> is the operation command, the log is sent to an operation command execution control unit <b>600</b>, and the DB control unit <b>362</b> applying the log <b>116</b> to the secondary DB <b>117</b> of the volume <b>310</b> so as to update the secondary DB <b>117</b>. In this case, the transaction control unit <b>361</b> can accept requirements from a business program <b>500</b> of the client computer <b>250</b> and a monitoring program <b>501</b> of the control apparatus <b>200</b> and DBA (DB Administrator).
p-0083The operation command execution control unit <b>600</b> is constituted by an operation command control unit <b>601</b> controlling an execution of the operation command analyzed by the transaction control unit <b>361</b>, and an operation command issuing unit <b>602</b> sending the control instruction to the secondary storage apparatus <b>113</b> to the disc control program <b>114</b> on the basis of the operation command.
p-0084In order to control an execution timing of the accepted operation command, the operation command control unit <b>601</b> inquires the transaction control unit <b>361</b> about the determining state of the transaction, and sends an instruction necessary for executing the operation command to the operation command issuing unit <b>602</b>. Further, the operation command control unit <b>601</b> inquires the transaction control unit <b>361</b> about an execution result obtained by executing the operation command, and sends any abnormality to the monitoring program <b>501</b> of the control apparatus <b>200</b>, thereby informing of the abnormality.
p-0085For example, in the case that the operation command for generating the snap shot is included in the log <b>116</b> following to the staticizing command, the operation command control unit <b>601</b> confirms with the operation command issuing unit <b>602</b> whether or not the staticizing is executed (the consistency of the transaction is secured).
p-0086The operation command control unit <b>601</b> inquires the transaction control unit <b>361</b> about whether or not all the transaction is determined (the staticizing is finished). If the staticizing is finished, the operation command control unit <b>601</b> instructs the snap shot generating command to the operation command issuing unit <b>602</b>.
p-0087The operation command issuing unit <b>602</b> instructs the disc control program <b>114</b> to finish the split of the mirror set <b>350</b> and execute the mirroring in a pair state. Accordingly, the secondary DB <b>117</b> in a state in which the transaction is completely determined is backed up as the secondary DB <b>118</b> to the volume <b>320</b>, and the snap shot at a time when the primary DBMS <b>101</b> writes the staticizing command on the log <b>106</b> is generated in the secondary DB <b>117</b> and the DB <b>118</b>.
p-0088When the generation of the snap shot is finished, the operation command control unit <b>601</b> instructs the disc control program <b>114</b> via the operation command issuing unit <b>602</b> to finish the pair state of the local mirror set <b>350</b> and become split, and restarts the update of the secondary DB <b>117</b> of the volume <b>310</b> while storing the snap shot at a certain time point (PiT) in the volume <b>320</b>.
h-0009[Process of Primary Site <b>1</b>]
p-0089<figref idrefs="DRAWINGS">FIG. 4</figref> is a flow chart showing an example of a process executed in the primary DBMS <b>101</b> of the primary site <b>1</b>. In the primary site <b>1</b>, mainly the primary DBMS <b>101</b> controls the primary DB <b>107</b>. In this case, it is assumed that the remote copy of the primary storage apparatus <b>103</b> is executed by the disc control program <b>104</b> at a predetermined timing.
p-0090First, in S<b>3</b>, the primary DBMS <b>101</b> accepts the requirement (the update requirement to the primary DB <b>107</b>) from the business program <b>500</b> or the like of the client computer <b>250</b>.
p-0091Next, it is determined whether or not the operation command is input to the primary DBMS <b>101</b> from the monitoring program <b>501</b> of the control apparatus <b>200</b> or DBA.
p-0092In the case that the operation command is not input, the step goes to S<b>5</b>, and the log corresponding to the update contents of the primary DB <b>107</b> is generated, and is written in the log <b>106</b> of the disc storage unit <b>131</b> in S<b>6</b>. Thereafter, S<b>7</b> executes writing in the DB buffer <b>102</b> or the primary DB <b>107</b> of the primary storage apparatus <b>103</b>, and the step goes back again to S<b>1</b>.
p-0093In the normal updating process from S<b>5</b> to S<b>7</b> mentioned above, after the log <b>106</b> is generated, the actual writing is executed and the primary DB <b>107</b> is updated. Further, the generated log <b>106</b> is remote copied to the secondary storage apparatus <b>113</b> by the disc control program <b>104</b> at the predetermined timing in the manner mentioned above.
p-0094On the other hand, in the case that the operation command is input in the determination in S<b>4</b> mentioned above, the step goes to S<b>8</b> and the contents of the operation command is analyzed.
p-0095The operation command is divided into a part commonly applied to the DB of the secondary site <b>2</b>, a part applied only to the primary site <b>1</b>, and a part applied only to the secondary site <b>2</b>.
p-0096As the operation command commonly applied to the primary site <b>1</b> and the secondary site <b>2</b>, there are a parameter change of the DBMS, a file extension command of the primary DB <b>107</b> and the secondary DB <b>108</b>, and the like.
p-0097As the operation command applied only to the primary site <b>1</b>, there are a performance measuring command of the primary DBMS <b>101</b>, and the like, and as the operation command applied only to the secondary site <b>2</b>, there are a performance measuring command of the secondary DBMS <b>111</b>, a snap shot generating command and the like.
p-0098Next, S<b>9</b> sets a process flag on the basis of a kind of the operation command analyzed in S<b>8</b> mentioned above. The process flag may be set, for example, such that 0<b>32</b> common to primary and secondary, 1=only to primary site, 2=only to secondary site, and the like. Further, the operation flag is added to the operation command.
p-0099Next, the primary DBMS <b>101</b> determines whether or not it is necessary to determine the transaction for executing the operation command. For example, the critical command for the contents of the primary DB <b>107</b>, such as the snap shot generating command, the file size change or the like, determines that it is necessary to determine the transaction, and the command having no relation to the contents of the primary DB <b>107</b> such as the performance measuring or the like determines that it is not necessary to determine the transaction.
p-0100In the case that it is not necessary to determine the transaction, the step goes to S<b>11</b> from S<b>2</b>, and the operation command is executed. After executing the operation command, S<b>12</b> determines whether or not the process to which the operation command is applied is normally finished.
p-0101In the case that the operation command is normally finished, the step goes to S<b>13</b>, and it is determined whether or not the process flag of the operation command is only the primary site <b>1</b> (the process flag=1). In the case of the operation command applied only to the primary site <b>1</b>, the operation command is not written in the log <b>106</b> and is broken, and the step goes back to S<b>1</b> as it is. Alternatively, the operation command may be written in the log after adding the information that the operation command can be executed in the secondary site <b>2</b>.
p-0102On the other hand, in the case that the process flag of the operation command is commonly applied or applied only to the secondary site <b>2</b>, it is necessary to transmit to the secondary site <b>2</b> via the log <b>106</b>. Accordingly, the step goes to S<b>14</b> so as to generate the corresponding log to the operation command, and after the log <b>106</b> is written in the disc storage unit <b>131</b> in S<b>15</b>, the step goes back to S<b>1</b>. The operation command written in the log <b>106</b> is transferred to the secondary storage apparatus <b>113</b> of the secondary site <b>2</b> by the remote copy, is interpreted by the DB/storage control unit <b>300</b> of the secondary site <b>2</b>, and is executed.
p-0103In the case that the operation command is not normally finished in accordance with the determination in S<b>12</b>, the step goes to S<b>16</b>, and an error is output. The error can be informed from the operation command execution control unit <b>506</b> to the control apparatus <b>200</b>. Further, the structure may be made such that the error is written in the log <b>106</b> so as to be transmitted to the secondary site <b>2</b>. After outputting the error, the step goes back to S<b>1</b>.
p-0104Next, in the case that the determination of the transaction is necessary for executing the operation command, in the determination in S<b>10</b> mentioned above, the step goes to S<b>18</b> and the staticization of the primary DB <b>107</b> is executed. After all the transactions are determined on the basis of the staticization, the step goes to S<b>2</b>, and the operation command is executed.
p-0105In the case that there is no transaction which is not determined yet in S<b>17</b> mentioned above, the step goes to S<b>2</b>, and the operation command is executed.
p-0106In accordance with the process mentioned above, in the case that the operation command is not input, after the log <b>106</b> is generated in response to the update requirement of the primary DB <b>107</b>, the log <b>106</b> is written in the primary storage apparatus <b>103</b>. In the case that the operation command is input, it is determined on the basis of the contents of the operation command whether or not it is necessary to determine the transaction. In the case that it is necessary, the operation command is executed after executing the staticization.
p-0107Further, after executing the operation command, the operation command except the operation command applied only to the primary site <b>1</b> is written in the log <b>106</b>, and the operation command is transmitted to the secondary site <b>2</b> via the log <b>106</b>.
h-0010[Process of Secondary Site]
p-0108<figref idrefs="DRAWINGS">FIG. 5</figref> is a flow chart showing an example of a process executed in the DB/storage control unit <b>300</b> of the secondary site <b>2</b>. In the secondary site <b>2</b>, the DB/storage control unit <b>300</b> mainly renews the secondary DB <b>117</b> and generates the snap shot. In this case, the secondary DBMS <b>111</b> accepts the searching and referring requirement from the business program <b>500</b> of the client computer <b>250</b>, however, since this matter is well known, a detailed description will be omitted here.
p-0109The DB/storage control unit <b>300</b> of the secondary site <b>2</b> first executes an initializing process in S<b>20</b>. The initializing process sets a reading position where the log <b>116</b> backed up in the secondary site <b>2</b> is read, or the like. In this case, the reading position is determined in correspondence to the previous end position or the like.
p-0110Next, in S<b>21</b> and S<b>22</b>, it is determined whether or not a backup finishing instruction is accepted from the monitoring program <b>501</b> of the control apparatus <b>200</b> or the business program <b>500</b> of the client computer <b>250</b> or DBA. In the case that the finishing instruction is executed, the step is finished after executing a predetermined after treatment (clear of variable and buffer) in S<b>23</b>.
p-0111If the finishing instruction is not generated, the step goes to S<b>25</b> from S<b>24</b>, and it is determined whether or not the log <b>116</b> is read to the terminal end. In the case that the log <b>116</b> is read to the terminal end, the step goes back to S<b>21</b> and a loop is repeated until the log <b>116</b> is added.
p-0112On the other hand, in the case that the log <b>116</b> is not read to the terminal end, the step goes to S<b>26</b>, and the log <b>116</b> is read. Further, in S<b>27</b>, the read log <b>116</b> is analyzed, and is divided into the log of the update difference in the primary DB <b>107</b>, and the log of the operation command.
p-0113In S<b>28</b>, it is determined whether or not the analyzed log <b>116</b> is constituted by the operation command. In the case that it is not constituted by the operation command, that is, in the case that it is constituted by the log of the update difference, the step goes to S<b>29</b>, the log <b>116</b> is applied to the secondary DB <b>117</b> of the primary volume <b>310</b> so as to be updated, and the determining state of the updated transaction is controlled in S<b>30</b>. Further, the step goes back to S<b>24</b>, and reading the log <b>116</b> is repeated until reaching the terminal end of the log <b>116</b>.
p-0114On the other hand, in the case that the read log <b>116</b> is constituted by the operation command, in the determination in S<b>28</b>, the step goes to S<b>31</b>, and the operation command is executed. If the operation command is normally finished, the step goes to S<b>24</b> from S<b>32</b>, and the next log <b>116</b> is read. In the case that any abnormality is generated in executing the operation command, the step goes to S<b>33</b>, an error is output, and the process is interrupted. In this case, it is sufficient that the output of the error informs of the matter that the error is generated in the control apparatus <b>200</b> and the client computer <b>250</b>. Further, after the interruption, the controller recovers the process.
h-0011[Generation of Snap Shot]
p-0115As discussed above, if the snap shot generation requirement is output from the monitoring program <b>510</b> of the control apparatus <b>200</b> by the primary DBMS <b>101</b> of the primary site <b>1</b> and the DB/storage control unit <b>300</b> of the secondary site <b>2</b>, the primary DB <b>107</b> of the primary site <b>1</b> is first staticized, and all the transactions are determined.
p-0116After finishing the staticization, the staticizing command and the snap shot generating command are written in the log <b>106</b>. The log <b>106</b> is remote copied to the secondary storage apparatus <b>113</b> of the secondary site <b>2</b> in accordance with the disc control program <b>104</b>.
p-0117In the secondary site <b>2</b>, the DB/storage control unit <b>300</b> reads the backed-up log <b>116</b> and executes the log application to the secondary DB <b>117</b> so as to synchronize with the primary DB <b>107</b>.
p-0118The staticizing command and the snap shot generating command written in the log <b>116</b> are sequentially interpreted by the DB/storage control unit <b>300</b>, and in the case of the staticizing command, the staticization of the secondary DB <b>117</b> is checked. Thereafter, the local mirror set <b>350</b> is set to a pair state on the basis of the snap shot generating command, and the secondary DB <b>117</b> of the primary volume <b>310</b> is written in the secondary volume <b>320</b> so as to set as the secondary DB <b>118</b>.
p-0119At this time, since the secondary DB <b>118</b> forms the contents of the primary DB <b>107</b> at the time when the primary DBMS <b>101</b> issues the staticizing command and all the transactions are in the determined state, it is possible to assure the contents of the searching and referring operations provided by the secondary DBMS <b>111</b> using the secondary DB <b>118</b>. Further, when the disability is generated in the primary site <b>1</b> and the operation is taken over to the secondary site <b>2</b> in accordance with the fail over, it is possible to rapidly restart the business by the secondary DBMS <b>111</b> without executing any special recovering process, by using the secondary DB <b>118</b> in which all the transactions have been determined. In other words, it is not necessary to recover the consistency of the transaction as in the backup in the block level, for example, in the prior art mentioned above, and it is possible to switch immediately from the primary site <b>1</b> to the secondary site <b>2</b>.
p-0120Further, after the generation of the snap shot is finished, it is possible to again set the local mirror set <b>350</b> to the split state, and it is possible to continue the backup on the basis of the log application in the secondary DB <b>117</b> of the primary volume <b>310</b>.
p-0121In this case, in the secondary DBMS <b>111</b>, there is shown an example that the searching and referring function is provided, however, since the local mirror set <b>350</b> of the secondary storage apparatus <b>113</b> is set to the split state except a time of generating the snap shot, and the primary volume <b>310</b> and the secondary volume <b>320</b> to which the log <b>116</b> is applied are independent, the renewing operation can be provided by using the secondary DB <b>118</b> of the secondary volume <b>320</b>. In this case, although the consistency with the primary DB <b>107</b> of the primary site <b>1</b> is not secured, it is possible to execute a test of version up of the DBMS in the secondary site <b>2</b>, for example. Accordingly, it is possible to execute a software development using the actual data, and it is possible to improve the added value of the DR system requiring a lot of cost.
p-0122Alternatively, in the case that the disability is generated in the primary site <b>1</b>, and the instruction of the fail-over is output to the DB/storage control unit <b>300</b> from the monitoring program <b>501</b> of the control apparatus <b>200</b>, the log <b>116</b> is applied to the secondary DB <b>117</b> of the primary volume <b>310</b>, and the secondary DB <b>117</b> is recovered. Thereafter, the primary volume <b>310</b> may be mounted on the secondary DBMS <b>111</b>, and may be switched from the primary site <b>1</b> to the secondary site <b>2</b>.
p-0123In this case, in the embodiment mentioned above, there is shown the example employing the mirror function of the mirror set <b>350</b>, however, a differential snap shot may be employed. The differential snap shot reflects the actual update after storing the data before being updated in the different disc region, in the case that the update is added to the volume to be subjected. Accordingly, since the snap shot area may store only the update portion in spite of all the primary volume <b>310</b>, it is possible to reduce the volumetric capacity of the secondary storage apparatus <b>113</b> secured for the snap shot. Further, since a plurality of snap shots are generated and are stored in the different regions, it is possible to control plural generation of snap shots.
p-0124Further, in the embodiment mentioned above, the staticizing command and the snap shot generating command are separately written in the log <b>106</b>, however, the structure may be made such that the DB/STORAGE control apparatus <b>300</b> can execute the staticization check and the mirroring by writing any one command in the log <b>106</b>.
p-0125Further, in accordance with the present invention, since the structure is made such that the remote copy of the log <b>106</b> is executed by the primary site <b>1</b> and the secondary site <b>2</b>, the operation command is written in the log <b>106</b> in addition to the update difference of the primary DB <b>107</b>, and the log application and the operation command are executed by interpreting the log <b>116</b> backed up by the secondary site <b>2</b>, it is possible to output the instruction of generating the snap shot to the secondary site <b>2</b>, without using the server network <b>121</b>, and it is possible to eliminate the load and the waiting time required for the communication so as to reduce the load of the primary site <b>1</b> and the secondary site <b>2</b>.
p-0126Further, in accordance with the present invention, since it is sufficient to add the function of writing the operation command in the log, and the function of analyzing the log so as to execute the log application of the update difference and the operation command, it is possible to easily achieve without requiring a large modification of the DBMS.
Second Embodiment
p-0127<figref idrefs="DRAWINGS">FIG. 6</figref> shows a second embodiment, in which a buffer <b>370</b> reading the log <b>116</b> is provided in the DB/storage control unit <b>300</b> of the secondary site <b>2</b> in accordance with the first embodiment, and the other structures are the same as those of the first embodiment mentioned above.
p-0128In the second embodiment, the DB/storage control unit <b>300</b> redoes (reproduces) the determined transaction by applying the log while analyzing the transaction.
p-0129In the present second embodiment, the primary site <b>1</b> writes the snap shot generating command in the log <b>106</b> at an optional time point regardless of the staticization.
p-0130Next, a description will be given of an example of a process executed by the DB/storage control unit <b>300</b> of the secondary site <b>2</b> with reference to <figref idrefs="DRAWINGS">FIG. 7</figref>.
p-0131First, in S<b>40</b>, the local mirror set <b>350</b> of the secondary storage apparatus <b>113</b> in the secondary site <b>2</b> is set to a pair state, the primary volume <b>310</b> and the secondary volume <b>320</b> are synchronized, and the secondary DB <b>118</b> is set to a snap shot at the starting. Further, when the synchronization is finished, a predetermined value indicating that the synchronization is finished is set to a state variable indicating the synchronization state. Further, a process after S<b>41</b> is executed while keeping the local mirror set <b>350</b> in the pair state.
p-0132In S<b>41</b>, a reading position of the log <b>116</b> of the secondary storage apparatus <b>113</b> in the secondary site <b>2</b> is determined on the basis of the previous state or the like in the same manner as the first embodiment mentioned above, and the step goes to a process after S<b>42</b>.
p-0133In S<b>43</b>, it is determined whether or not the instruction of finishing the backup is accepted from the monitoring program <b>501</b> of the control apparatus <b>200</b> or the business program <b>500</b> of the client computer <b>250</b> or DBA. In the case that the finish instruction is output, the step is finished after a predetermined after treatment (the clearing step of the variable or the buffer) is executed in S<b>44</b>.
p-0134If the finish instruction is not output, the step goes to S<b>45</b>, it is determined whether or not the log <b>116</b> is read to the terminal end. In the case that the log is read to the terminal end, the step goes back to S<b>42</b> and the loop is repeated until the log <b>116</b> is added.
p-0135On the other hand, in the case that the log <b>116</b> is read to the terminal end, the step goes to S<b>46</b> and the log <b>116</b> is read in the buffer <b>370</b>. Further, in S<b>47</b>, the read log <b>116</b> is analyzed, and is divided into the log in the update difference of the primary DB and the log of the operation command, and it is determined whether or not the analyzed log <b>116</b> is constituted by the operation command. In the case that the log is not constituted by the operation command, that is, the log is constituted by the log of the update difference, the step goes to S<b>48</b>, the log <b>116</b> is applied to the secondary DB <b>117</b> of the primary volume <b>310</b>. In the case that the transaction is determined, the secondary DB <b>117</b> is updated by redoing (reproducing).
p-0136As a result, since the local mirror set <b>350</b> is in the pair state, the secondary DB <b>118</b> of the secondary volume <b>320</b> is simultaneously updated, and the most recent snap shot is generated.
p-0137After applying the log <b>116</b>, the step goes back to S<b>42</b>, and the reading or the log <b>116</b> is repeated until the log <b>116</b> reaches the terminal end.
p-0138On the other hand, in the case that the read log <b>116</b> is constituted by the snap shot preparing command in accordance with the determination in S<b>47</b>, the step goes to S<b>49</b>, and after it is confirmed that the state variable is constituted by a predetermined value indicating the synchronous state, the local mirror set <b>350</b> is set to the split state in S<b>50</b>, and the secondary DB <b>117</b> of the primary volume <b>320</b> and the secondary DB <b>118</b> of the secondary volume <b>320</b> are separated in the synchronous state.
p-0139If the snap shot generating command is normally finished, the step goes to S<b>51</b>, and it is determined whether or not the command is normally finished. In the case that no abnormality is generated by executing the snap shot generating command, the step goes to S<b>52</b>, and the process is interrupted by outputting an error. In this case, it is sufficient that the output of the error informs of the matter that the error is generated in the control apparatus <b>200</b> and the client computer <b>250</b>. Further, after the interruption, the controller recovers the process.
p-0140In accordance with the processes mentioned above, the DB/storage control unit <b>300</b> of the secondary site <b>2</b> always recovers the backup of the primary DB <b>107</b> by applying the log <b>116</b> read into the buffer <b>370</b> to the secondary DB <b>117</b> and redoing the determined transaction. Further, at the time of applying the log <b>116</b>, the local mirror set <b>350</b> is set to the pair state, and the primary volume <b>310</b> and the secondary volume <b>320</b> are set to be synchronized.
p-0141Further, in the case that the snap shot generating command is included in the log <b>116</b>, the secondary DB <b>118</b> of the secondary volume <b>320</b> finishes the log application and is disconnected by changing the local mirror set <b>350</b> to the split state.
p-0142The secondary DB <b>118</b> of the secondary volume <b>320</b> becomes the consistent snap shot to which the transaction determining the snap shot generating command in the side of the primary site <b>1</b> to the issuing time point is reflected.
p-0143As discussed above, in the case that the staticization is not executed, the determined transaction is always redone, and the local mirror set <b>350</b> is set to the split state at a time when the snap shot preparing command comes to the secondary site <b>2</b>, whereby it is possible to generate the snap shot having the consistency of the transaction in the secondary volume <b>320</b>.
p-0144Further, since it is sufficient to only write the snap shot generating command in the log <b>106</b> without executing the staticization, in the primary site <b>1</b>, it is possible to make the load required for processing the snap shot generation extremely small. In this case, the snap shot generating command may be input to the primary site <b>1</b> from the monitoring program <b>501</b> of the control apparatus <b>200</b> in the same manner as the first embodiment mentioned above, and the primary DBMS <b>101</b> may issue the snap shot generating command (write in the log <b>106</b>) at a predetermined cycle.
Modified Embodiment 1
p-0145<figref idrefs="DRAWINGS">FIG. 8</figref> shows an example in a case of working the process in the DB/storage control unit <b>300</b> in accordance with the second embodiment with the searching and referring operation starting process of the secondary DBMS <b>111</b> in the secondary site <b>2</b>.
p-0146S<b>40</b> to S<b>52</b> in <figref idrefs="DRAWINGS">FIG. 8</figref> are the same as those of the second embodiment mentioned above, and <figref idrefs="DRAWINGS">FIG. 8</figref> is different in that a process (S<b>61</b>) of noticing that the snap shot is generated in the secondary DBMS <b>111</b> is added after the process in S<b>50</b>.
p-0147S<b>70</b> to S<b>73</b> in <figref idrefs="DRAWINGS">FIG. 8</figref> show an example of the searching and referring operation starting process of the secondary DBMS <b>111</b>.
p-0148S<b>70</b> executes an initializing process for the secondary DBMS <b>111</b> starting the searching and referring operation, and S<b>71</b> waits until the notice from the DB/storage control unit <b>300</b> reaches.
p-0149When the secondary DBMS <b>111</b> receives the notice that the generation of the snap shot is finished from the DB/storage control unit <b>300</b>, the secondary DBMS <b>111</b> mounts the secondary DB <b>118</b> of the split secondary volume <b>320</b>, in S<b>72</b>. Thereafter, the providing of a predetermined operation is started by using the mounted secondary DB <b>118</b>, in S<b>73</b>.
p-0150The secondary DBMS <b>111</b> can execute the searching and referring operation on the basis of the DB having consistency in the transaction, by working the DB/storage control unit <b>300</b> with the secondary DBMS <b>111</b> and mounting the volume in which the secondary DBMS <b>111</b> generates the snap shot after finishing the generation of the snap shot.
p-0151In this case, the operation of the secondary DBMS <b>111</b> is not limited to the referring operation as mentioned above, may be constituted by executing the update. For example, the structure may be made such that a batch process having a high processing load such as a monthly process and an end-of-period process is executed by the secondary DBMS <b>111</b> by using the snap shot. Accordingly, it is possible to disperse the batch process actually executed in the primary DBMS <b>101</b> into the secondary DBMS <b>111</b>, and it is possible to execute the batch process having the high processing load in the secondary site <b>2</b> while preventing the response of the primary site <b>1</b> from being lowered.
Modified Embodiment 2
p-0152<figref idrefs="DRAWINGS">FIG. 9</figref> shows a structure obtained by replacing the secondary storage apparatus of the secondary site <b>2</b> in accordance with the first embodiment mentioned above by NAS <b>113</b>A, and the other structures are the same as those of the first embodiment mentioned above.
p-0153The NAS <b>113</b>A is provided with the disc control program <b>114</b>, the cash <b>115</b>, the local mirror set constituted by the disc storage units <b>302</b> and <b>303</b>, and the disc storage unit <b>301</b>, in the same manner as the secondary storage apparatus <b>113</b> in accordance with the first embodiment mentioned above, and the DB/storage control unit <b>300</b> is executed in addition to the disc control program <b>114</b>, in a control unit (not shown) of the NAS <b>113</b>A.
p-0154In this example, the exclusive apparatus <b>301</b> for executing the DB/storage control unit <b>300</b> shown in the first embodiment mentioned above is not required, and it is possible to lower a cost required for constructing and maintaining the DR system.
Modified Embodiment 3
p-0155<figref idrefs="DRAWINGS">FIG. 10</figref> shows a structure obtaining by replacing the NAS <b>113</b>A in accordance with the modified embodiment 2 mentioned above by SAN server <b>113</b>B, and the other structures are the same as those of the modified embodiment 2 mentioned above.
p-0156The SAN server <b>113</b>B is provided with the disc control program <b>114</b>, the cash <b>115</b>, and the DB/storage control unit <b>300</b>, is connected to the primary storage apparatus <b>103</b> of the primary site <b>1</b> via the storage network <b>120</b>, and is connected to the disc storage units <b>301</b>, <b>302</b> and <b>303</b> via a storage area network (SAN).
p-0157The disc storage units <b>302</b> and <b>303</b> may construct the mirror set <b>350</b> by the SAN server <b>113</b>B, or may construct the mirror set <b>350</b> in one disc storage unit.
p-0158In this case, in the first and second embodiment, there is shown the case that the monitoring program <b>501</b> of the control apparatus <b>200</b> requires the generation of the snap shot to the primary site <b>1</b>, however, the primary DBMS <b>101</b> may instructs the generation of the snap shot (the generation of the log <b>106</b>) at a predetermined timing (in the case that the cycle or the state of the DB <b>107</b> satisfies a predetermined condition).
Modified Embodiment 4
p-0159The description is given by using the snap shot command as the operation command, however, the operation command may be constituted by a command of DBMS/storage/AP or the like.
p-0160A description will be given below by using an example in which the DB file is extended, with reference to <figref idrefs="DRAWINGS">FIG. 11</figref>.
p-0161In this case, it is assumed that the log file <b>106</b> and the DB file <b>107</b> exist respectively in the disc storage unit <b>131</b> and the disc storage unit <b>130</b> in which the log and DB are stored in the primary site <b>1</b>.
p-0162It is assumed in the same manner that the secondary log file <b>116</b> and the secondary DB file <b>117</b> exist in the secondary site <b>2</b>.
p-0163In the case that the insertion is repeatedly executed, it is necessary to extend a size of the DB file <b>107</b>. In specific, the extension of the file is executed subsequently after executing the extension of the region of the disc storage unit first.
p-0164<figref idrefs="DRAWINGS">FIG. 11A</figref> shows an initial state before extending the disc storage unit and the file. A database administrator (DBA) and user application (UAP) input an operation command <b>1100</b> in the order of a disc storage unit extension and a file extension to the primary DBMS <b>101</b> from the client computer or the control apparatus shown in the first embodiment mentioned above.
p-0165<figref idrefs="DRAWINGS">FIG. 11B</figref> shows a state after the operation command is executed.
p-0166When receiving the operation command, the primary DBMS <b>101</b> executes the operation command, and packs the operation command in the log so as to write the operation command in the log file <b>106</b>.
p-0167At this time, in order to execute the operation command under the uniform DB state in the primary and secondary sites, the staticization as mentioned above may be executed in the primary site before executing the operation command.
p-0168In execution of the operation command, the different disc storage unit <b>132</b> is first secured in the secondary storage <b>103</b>, and the DB file <b>1071</b> is extended subsequently so as to be astride the disc storage units <b>130</b> and <b>132</b>. In this case, the file obtained by extending the DB file <b>107</b> corresponds to the DB file <b>1071</b>.
p-0169<figref idrefs="DRAWINGS">FIG. 11C</figref> shows a state in which the operation command is executed in the secondary site <b>2</b>.
p-0170In the secondary site <b>2</b>, the DB/storage control unit <b>300</b> monitors the log file <b>116</b> and executes the log application so as to update the DB file <b>117</b>.
p-0171The log file <b>116</b> is updated by the remote copy <b>140</b>, however, as a result of the update, when the operation command packed in the log in <figref idrefs="DRAWINGS">FIG. 11B</figref> is read, the log is analyzed and the operation command is executed.
p-0172In this case, two commands constituted by the disc storage unit extension and the file extension are packed.
p-0173The different disc storage unit <b>303</b> is first secured in the secondary storage <b>113</b>, and the DB file <b>1171</b> is subsequently extended so as to be astride the disc storage units <b>302</b> and <b>303</b>. In this case, the file obtained by extending the DB file <b>107</b> corresponds to the DB file <b>1071</b>.
p-0174In the case that the timing for executing the operation command is displaced between the primary and secondary sites, for example, in the case that the extension of the DB file <b>1171</b> in the secondary site <b>2</b> is different from the original timing (the extension timing in the primary site <b>1</b>), the insertion to be executed after the extension may be possibly executed in the DB file <b>117</b> before being extended, in the secondary site <b>2</b>. In this case, an error is generated.
p-0175However, in the case of working with the staticization as in the present invention, it is possible to secure to execute the operation command at the same timing and order in the DB file in the uniform state. Accordingly, the error mentioned above is not generated.
Contents6
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
Every citation, both waysCites: the store holds 17 of 18
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2009327805A1 | Cited by | United States of America | Pre-grant |
| US9268650B2 | Cited by | United States of America | Applicant |
| US7908514B2 | Cited by | United States of America | Search report |
| US2003208511A1 | Cites | United States of America | Applicant |
| US2004098425A1 | Cites | United States of America | Applicant |
| US5796934A | Cites | United States of America | Search report |
| US6408310B1 | Cites | United States of America | Search report |
| US6487560B1 | Cites | United States of America | Applicant |
| US6718348B1 | Cites | United States of America | Applicant |
| US6832330B1 | Cites | United States of America | Search report |
| US6895417B2 | Cites | United States of America | Applicant |
| US6925476B1 | Cites | United States of America | Applicant |
| US6934725B1 | Cites | United States of America | Search report |
| US6934877B2 | Cites | United States of America | Search report |
| US6948089B2 | Cites | United States of America | Search report |
| US7028140B2 | Cites | United States of America | Search report |
| US7082446B1 | Cites | United States of America | Search report |
| US7210061B2 | Cites | United States of America | Search report |
| US7272686B2 | Cites | United States of America | Search report |
| US7275185B2 | Cites | United States of America | Search report |
| Microsoft Computer Dictionary, Fifth Edition; 2002; Microsoft Press; pp. 357, 498-499. | Non-patent | – | Search report |
| Mikkelsen, Claus, "The Hitachi NanoCopy(TM) Advantage-An Industry First for Point-in-Time and Real-Time Copy," [online], "searched on Jul. 16, 2004" via the Internet http://www.hds.com/pdf/wp134-nanocopy.pdf. 17 pages. | Non-patent | – | Applicant |
| Oracle Data Guard, "Overview of Oracle Data Guard Functional Components", "Searched on Jul. 16, 2004", via the Internet, http://otn.oracle.com/deplay/availability/htdocs/DataGuardOverview.html. 6 pages. | Non-patent | – | Applicant |
4 members in 2 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004223776 | Japan | A | |
| 2004223776 | Japan | A | |
| 2004223776 | – | – | – |
| JP20040223776 | – | – | – |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| US2006026452A1 | United States of America | A1 | |
| JP2006048103A | Japan | A | |
| US7529964B2This record | United States of America | B2 | |
| JP4484618B2 | Japan | B2 |
38 transactions on the USPTO file
Allowed after 1 non-final rejection and 1 final rejection.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Mail-Record Petition Decision of Granted to Make SpecialMP003 | MP003 | |
| Record Petition Decision of Granted to Make SpecialP003 | P003 | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Petition EnteredPET. | PET. | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Initial Exam Team nnIEXX | IEXX |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 7529964
- Publication, EPODOC
- US7529964
- Application
- 10930832
- Application, DOCDB
- 93083204
- Application, EPODOC
- US20040930832
Titles
- English
- Data duplication method in a disaster recovery system
Patent term adjustment
- A delay
- +772 daysthe office missed an examination deadline
- Applicant delay
- −63 days
- Net adjustment
- 709 days
Classification
- CPC, 2
- G06F11/2097
- G06F11/1471
- IPC, 1
- G06F11 00
- USPC, 4
- 714006230
- 714006300
- 714006310
- 714020000